Exploitation observed; activity peaked at 7 mentions and remains active
Immediate actions
Patch proftpd proftpd systems immediately
Assume compromise if assets are exposed
Hunt for exploitation attempts and persistence artifacts
Increase monitoring for publicly documented tradecraft
Recommended action window: Immediate (within 24h)
NVD description
mod_sql in ProFTPD before 1.3.9a allows remote attackers to execute arbitrary code via a username, in scenarios where there is logging of USER requests with an expansion such as %U, and the SQL backend allows commands (e.g., COPY TO PROGRAM).
Active Exploitation1Disclosure3Exploit1General1PoC1
2026-05-01
2
Disclosure1PoC1
2026-05-02
1
Patch1
2026-05-04
2
Active Exploitation1General1
2026-05-07
1
Disclosure1
2026-05-11
1
Patch1
2026-07-17
1
Exploit1
2026-08-05
1
PoC1
2026-08-14
1
Patch1
2026-08-25
3
General1Patch1PoC1
2026-09-01
1
Exploit1
>Full discourse20 posts
LeftenantZero@LeftenantZero·
PoC
CVE-2026-42167, a high severity vuln in ProFTPD I discovered, was just published today! Attackers can use it to bypass auth and even execute arbitrary code in some cases.
Check out my write up for full technical details, including a working POC!
https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce https://t.co/uFyjwlO7xs
Post summary
The author announces the newly discovered CVE-2026-42167 against ProFTPD, highlights its high severity, and provides a link to a write-up containing a working proof‑of‑concept that demonstrates auth bypass and possible RCE, but does not report active exploitation or a patch.
FTP `USER` alone. No password. SQLLog thinks your quote-wrapped name is “already escaped.”
CVE-2026-42167 (CVSS 8.1) - ProFTPD `mod_sql` ≤ 1.3.9.
Chain: `is_escaped_text()` skips escaping for `'…'` → `%U` in `SQLNamedQuery` becomes raw SQL on failed login (`SQLLog ERR_*`) → stacked `INSERT` plants uid 0 / `homedir=/` backdoor user → or PostgreSQL `COPY TO PROGRAM` = RCE on the DB host.
Config gate: SQLLog interpolating attacker-controlled `%U` (common hosting pattern). Patch to 1.3.9a or kill mod_sql logging of pre-auth vars.
PoC: https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc
Writeup: https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce
#ProFTPD#SQLi#RCE#InfoSec
~160k ProFTPD on Shodan. If yours logs `%U` pre-auth, this is not theoretical.
Caught a released-vs-master patch gap in ProFTPD's mod_sql.c (CVE-2026-42167, CVSS 8.1 High).
The fix existed in master but never got backported to the 1.3.9 release branch, so anyone running the official release was still exposed. We flagged it, and the maintainer confirmed and shipped the backport within a day.
First of many.
Post summary
The post reports a high‑severity bug in ProFTPD’s mod_sql.c that was patched quickly after being flagged. The maintainer backported the fix to the released 1.3.9 branch within a day.
Found an open directory hosting a layered financial fraud operation across three simultaneous tracks: a Magecart-style card skimmer chain, a mass CVE exploitation framework, and a trojan distributed through Chinese streaming software packaging. All of it feeding the same PII collection pipeline.
The skimmer track starts with FOFA. The actor runs automated queries targeting WooCommerce, Magento, and Stripe-integrated checkout pages, sorting results into structured target lists by category: builder_woo_checkout, stripe_woo_checkout, magento_checkout, checkout_cdn_js. Output lands in pii_consolidated.csv, with a second batch file visible alongside it. This has been running in passes.
The skimmer component is a WooCommerce and Stripe-targeted Magecart payload. Injection engine supports page-level download, mitmproxy transparent proxy, and browser console delivery. C2 receiver runs on the same host. Target profile: Stripe Elements checkout pages, WooCommerce wc-ajax endpoints.
The exploitation track runs in parallel. poc_scanner.py drives 300 concurrent probes against FOFA-sourced targets through a three-stage pipeline: liveness check, service fingerprinting, then PoC verification. CVEs being actively weaponized:
CVE-2026-21858 — n8n unauthenticated RCE, CVSS 10.0
CVE-2026-6815 — Casdoor path traversal to RCE, CVSS 9.8
CVE-2026-32604 — Spinnaker shell injection, CVSS 10.0
CVE-2026-34486 — Tomcat Tribes auth bypass to RCE, CVSS 9.8
CVE-2026-25212 — Percona PMM RCE, CVSS 9.9
CVE-2026-35273 — PeopleSoft unauthenticated SSRF to RCE, CVSS 9.8
CVE-2026-23744 — MCPJam Inspector unauthenticated RCE, CVSS 9.8
CVE-2026-42167 — ProFTPD
CVE-2026-6182 — SQL injection auth bypass
CVE-2025-24587, CVE-2025-4396
A separate WordPress track runs alongside: mass SQL injection via wp_sqli_mass.py, aggressive dump via wp_aggressive_dump.py, PhpMyAdmin brute-force against the same pool.
The trojan track is socially engineered. 直播助手化.v2.exe presents as a legitimate Chinese streaming helper application. VMProtect 3.2–3.5 wrapping. 29/70 on VirusTotal at time of analysis. Family: flystudio, chinad, dlii. It ships with HPSocket4C.dll, pb.dll, pb64.dll, and gzip.dll as side-loaded components. The infection surface is Chinese-speaking streaming users who would recognize the product name as familiar tooling. C2 routes through v2ray.
Two license spoofing servers complete the toolkit. bypass_server.py impersonates http://premium.dotbypasser.workers.dev, handling RSA-OAEP encrypted license exchange and returning forged validation responses with 10-year expiry timestamps. fake_auth_server.py covers a separate streaming platform, impersonating http://api.vmks.cn and related domains, returning fake authorization tokens. Both appear to serve tooling distribution rather than direct victim infrastructure.
One additional finding on the C2 host: evidence of AI-assisted offensive operations. A DeepSeek API configuration points to http://api.deepseek.com through an Anthropic-compatible interface, and a structured offensive security framework containing 70+ purpose-built skill modules for vulnerability classes including SQLi, XSS, SSRF, RCE, IDOR, OAuth, SAML, cloud misconfiguration, Kubernetes, CI/CD, M365/Entra, VMware vCenter, and supply chain recon. The actor is running systematized, AI-assisted attack methodology. This pattern is increasingly documented across financially motivated operations.
OPSEC failure on an otherwise capable operator. filter_cn.py is on the box and actively used. It strips Chinese IP ranges from FOFA output sets before exploitation runs begin. The actor is deliberately skipping domestic targets, a consistent behavioral marker across Chinese financially motivated operations. Additionally, the FOFA API credential is hardcoded in cleartext across the client scripts. Easy attribution anchor.
Post summary
The post details an active threat actor with ready-to-use scripts that weaponize multiple CVEs, perform mass exploitation, and exfiltrate data, underscoring the operational readiness and scale of the operation.
Independent reproduction, code-level root-cause analysis, and realistic-exposure write-up for CVE-2026-42167 (ProFTPD mod_sql is_escaped_text() bypass). https://github.com/dinosn/proftpd-CVE-2026-42167-analysis
Post summary
Shares a GitHub analysis demonstrating a bypass in ProFTPD's mod_sql module (CVE‑2026‑42167), including code‑level reproduction but no active exploitation or patch info.
GitHub - ZeroPathAI/proftpd-CVE-2026-42167-poc: POCs to demonstrate CVE-2026-42167 in ProFTPD · GitHub https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc
Post summary
A GitHub repository hosts proof‑of‑concept code demonstrating CVE‑2026‑42167 against ProFTPD; it does not provide evidence of active exploitation, patches, or a false‑positive claim.
ProFTPD mod_sql still has a pre-auth backdoor path if SQLLog interpolates %U inside quotes!!!
CVE-2026-42167 is_escaped_text() in contrib/mod_sql.c misses the break-out. Pre-auth %U injects a uid 0 user into the auth table. PostgreSQL COPY TO PROGRAM is the RCE path, and only if that DB role is superuser.
Fixed in 1.3.9a / 1.3.10rc1. Config-dependent. Not a default install.
https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc
#Cybersecurity#AI#AISecurity#MCP#Claude#GPT#Infosec#Trending#NetworkSecurity#SQLi#RCE
CVE-2026-42167: ProFTPd: SQL injection https://www.openwall.com/lists/oss-security/2026/05/01/4
Depending on configuration, the flaw can be exploited before authentication and may lead to authentication bypass, privilege escalation, or remote code execution. Fixed in 1.3.9a.
Post summary
CVE-2026-42167 is an SQL injection in ProFTPd that can lead to authentication bypass and remote code execution, and the issue is fixed in version 1.3.9a.
CVE-2026-42167: pre-auth SQL injection in ProFTPD
An SQL injection vulnerability was discovered in the "mod_sql" module of the ProFTPD FTP server. It is tracked as CVE-2026-42167 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-42167) and has a CVSS score of 8.1.
The issue was caused by the "is_escaped_text()" function. It considered a string safely escaped if it:
• started with "'"
• ended with "'"
• contained no other single quotes
This heuristic was originally added for the trusted internal call "mod_quotatab_sql", to avoid double escaping. However, "mod_sql" applied it to all data, including values received from the FTP client.
As a result, the server accepted user input as part of an SQL command such as "USER '<SQL payload>'". The value was passed to "SQLNamedQuery", passed the check as “already escaped,” and was inserted into the query without calling "sql_escapestring".
The attack worked even when authentication failed, if the server logged "USER" commands through "SQLLog ERR_*".
When PostgreSQL was used, an attacker could leverage stacked queries to add a new FTP account to the SQL table with "UID 0" and the home directory "/", and then authenticate as that account. If the database allowed "COPY TO PROGRAM" or a similar mechanism, the SQL injection could lead directly to command execution.
In the fix, the developers separated data sources: client-supplied variables are now forcibly escaped before entering the shared resolver. The flaw had existed since November 2020, and the patch was introduced in commit "e6f72848".
Article: https://nefariousplan.com/posts/proftpd-mod-sql-the-heuristic-was-for-one-caller
PoC: https://github.com/dinosn/proftpd-CVE-2026-42167-analysis
#dbugs_attacks
Post summary
The post discloses a pre‑auth SQL injection in ProFTPD’s mod_sql module, provides a PoC link, details the technical exploitation method, and notes the available patch.
Ready to bypass authentication and execute remote commands on a ProFTPD server? ⚡️🚨
Just added to Hackviser Labs: ProFTPD Authentication Bypass & Remote Code Execution (CVE-2026-42167) 🔥
Join Hackviser to start the lab now 🚀 https://t.co/IObTCtcMd7
Post summary
A new ProFTPD authentication bypass and remote code execution vulnerability (CVE‑2026‑42167) has been added to Hackviser Labs, likely including a proof‑of‑concept exploit for testing purposes.
🔴 ProFTPD'de CVSS 8.1 seviyesinde kritik bir açık: CVE-2026-42167
ProFTPD'nin mod_sql modülündeki SQL Injection açığı, uygun yapılandırmalarda kimlik doğrulama gerektirmeden istismar edilebiliyor.
Açık; kimlik doğrulama atlatma, yetki yükseltme ve bazı PostgreSQL yapılandırmalarında uzaktan kod çalıştırmaya (RCE) kadar ilerleyebiliyor.
Üstelik açık için çalışan PoC'ler de yayınlandı.
Etkilenen sürümler için ProFTPD'nin 1.3.9a ve üzeri sürüme güncellenmesi öneriliyor.
Post summary
CVE-2026-42167 is a critical SQL injection flaw in ProFTPD's mod_sql that can lead to authentication bypass, privilege escalation, and remote code execution; PoCs have been released and the vendor recommends updating to 1.3.9a or later.
#exploit#AppSec
1⃣. CVE-2026-42167:
RCE, authentication bypass, and privilege escalation in ProFTPD <=1.3.9 https://github.com/ZeroPathAI/proftpd-CVE-2026-42167-poc
2⃣. CVE-2026-41940:
Critical vulnerability in cPanel & WHM allowing session hijacking and authentication bypass via CRLF injection https://labs.watchtowr.com/the-internet-is-falling-down-falling-down-falling-down-cpanel-whm-authentication-bypass-cve-2026-41940/
3⃣. CVE-2026-40478:
Thymeleaf server-side template injection vulnerability https://snyk.io/blog/thymeleaf-injection/
4⃣. CVE-2026-3854:
RCE in GitHub*com/GitHub Enterprise Server https://www.wiz.io/blog/github-rce-vulnerability-cve-2026-3854
5⃣. CVE-2026-20079:
Critical Cisco FMC Zero-Day https://github.com/0xBlackash/CVE-2026-20079
Post summary
The tweet lists five CVEs, each with an explicit proof‑of‑concept or functional exploit link, but does not reference active wild exploitation or vendor patches.
최근 ZeroPath Research를 통해 ProFTPD의 특정 모듈(mod_sql)에서 발생하는 심각한 보안 취약점(CVE-2026-42167)이 공개되었습니다.
이 취약점은 인증 우회는 물론, 특정 조건에서 서버의 제어권을 완전히 탈취할 수 있는 위험성을 내포하고 있습니다.
https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce https://t.co/TNDSvHGs7Q
Post summary
ZeroPath Research has disclosed a critical authentication bypass and privilege escalation flaw in ProFTPD’s mod_sql module (CVE‑2026‑42167), with a link to detailed information, but no active exploitation or patch information is provided.
Linux-Administratoren werden wohl (k)ein langes Wochenende haben: proFTPD (CVE-2026-42167), cPanel/WHM (CVE-2026-41940) und insb. CopyFail (CVE-2026-31431). Für CopyFail existieren bereits Go- und C-Forks. https://t.co/MzUsl0x0hu
Post summary
The tweet announces three CVEs affecting Linux systems and notes that code forks already exist for CopyFail, but it does not report active exploitation or patches.
🚨 CVE-2026-42167 - high 🚨
ProFTPD mod_sql - Preauth User Backdoor
> ProFTPD mod_sql before 1.3.10rc1 contains a remote code execution caused by unsafe us...
👾 https://cloud.projectdiscovery.io/library/CVE-2026-42167
@pdnuclei#NucleiTemplates#cve
Post summary
The tweet announces the discovery of CVE‑2026‑42167, a pre‑authentication RCE backdoor in ProFTPD mod_sql before version 1.3.10rc1, and links to a resource with further details.
🚨 HIGH - ProFTPD mod_sql Unauth RCE (CVE-2026-42167)
A vulnerability in mod_sql allows unauthenticated RCE via malicious SQL logging expansions. Attackers can use crafted usernames to break SQL strings and execute OS-level commands through the database backend.
👉 Affected: < 1.3.10rc1 | Upgrade to v1.3.10rc1
Post summary
The post announces an unauthenticated RCE in ProFTPD mod_sql (CVE‑2026‑42167) and advises upgrading to v1.3.10rc1 to remediate the issue.
ZeroPath discovered CVE-2026-42167 in ProFTPd, one of the internet's most popular FTP daemons. The flaw allows for auth bypass and even pre-auth RCE in some configurations. Update to 1.3.9a now!
https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce
Take a look at the blog for technical details and a working POC.
Post summary
ZeroPath announced CVE-2026-42167 in ProFTPd, revealing an authentication bypass that can lead to pre‑auth remote code execution, and supplied a working PoC plus a patch recommendation to upgrade to version 1.3.9a.
Constantin Milos ♏@Tinolle infosec.exchange@Tinolle1955·
Disclosure
CVE-2026-42167 Allows Auth Bypass And RCE In ProFTPD
https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce
Post summary
CVE‑2026‑42167 is a newly disclosed flaw in ProFTPD that permits authentication bypass and remote code execution; the announcement provides technical details but no PoC, patch, or evidence of active exploitation.
The post announces the discovery of a CVE‑2026‑42167 vulnerability in ProFTPD’s mod_sql module, explains its technical aspects (SQL injection leading to RCE), and indicates that a fix is available.
Warning: SQL injection in #ProFTPD mod_sql actively exploited! #CVE-2026-42167 CVSS: 8.1. Pre-auth RCE & auth bypass via logging % expansions. 162k+ internet-facing instances at risk (https://zeropath.com/blog/proftpd-cve-2026-42167-auth-bypass-privesc-rce). Upgrade to ≥1.3.9a NOW! #Patch#Patch#Patch http://www.proftpd.org/docs/RELEASE_NOTES-1.3.10rc1
Post summary
The post warns of a high‑severity SQL injection vulnerability in ProFTPD that is being exploited in the wild; it urges immediate patching to version 1.3.9a and directs readers to detailed technical information and a patch reference.